Your phone suddenly shows no service. A password-reset email appears that you did not request. Then your bank sends an alert about a transfer. Those can be signs of SIM-swap or port-out fraud, where an attacker convinces a mobile provider to move a victim’s phone number to a SIM or account the attacker controls.
The Federal Trade Commission warns that text-message verification may not stop a SIM-swap attacker because the criminal can receive the verification code after taking control of the number. The FTC recommends an authentication app or security key for sensitive accounts when those options are available.
What happens in a SIM-swap attack?
A phone number is often used as a recovery channel for email, banking and social accounts. If a criminal takes over that number, the attacker can try to reset passwords or satisfy SMS-based multifactor authentication. The damage can quickly spread from the mobile account to email, financial accounts and online identities.
What to do in the first hour
- Contact the mobile carrier immediately. Ask it to restore control of the number and lock down unauthorized changes.
- Secure your primary email account. Email is often the key to resetting other accounts. Change the password from a trusted device and review recovery methods.
- Contact banks and card issuers. Report unauthorized transfers or charges using official contact channels.
- Change passwords on affected accounts. Use unique passwords and do not reuse the compromised credential.
- Replace SMS MFA where possible. Move sensitive accounts to an authenticator app or hardware security key when supported.
- Preserve evidence. Save carrier messages, login alerts, transaction records, screenshots and case numbers.
- Report identity theft when appropriate. IdentityTheft.gov provides a recovery plan for U.S. consumers.
Where personal cyber insurance may help
Personal cyber policies and cyber endorsements vary. Depending on the form, benefits can include identity restoration services, access to specialists, cyber extortion assistance, data recovery, legal consultation or reimbursement for specifically defined financial losses. Deductibles, sublimits and exclusions matter.
Our personal cyber insurance guide explains the major coverage categories. A separate identity theft insurance guide covers restoration expenses and recovery services.
| Loss or service | Could be relevant to cyber/identity coverage? | What to verify |
|---|---|---|
| Identity restoration specialist | Often a feature of identity or cyber products | Provider requirements and service limits |
| Unauthorized transfer or online fraud loss | Some policies offer defined fraud coverage | Covered event, sublimit, exclusions and bank reimbursement |
| Lost wages / document replacement | May appear in identity restoration benefits | Eligible expenses and documentation |
| Device repair or data recovery | Can be a separate cyber benefit | Whether SIM swap itself triggers that section |
Insurance and bank reimbursement are separate issues
Do not delay reporting an unauthorized transaction while you search for an insurance policy. Financial institutions have their own legal and contractual procedures for unauthorized activity, and reporting deadlines can matter. A cyber insurer may require you to pursue available recovery from a bank, carrier or other responsible party before it pays certain amounts.
Likewise, insurance should not be treated as a replacement for account security. Coverage applies only to defined events and losses. Our online scam loss guide explains why voluntary transfers, account takeover and unauthorized transactions can be treated differently.
How to make SIM swapping harder
Use a carrier PIN or account password
The FTC recommends setting a PIN or password on the cellular account to help protect against unauthorized changes. Ask the carrier whether it also offers port-out locks or additional account security controls.
Prefer stronger MFA for sensitive accounts
When available, authenticator apps and security keys reduce dependence on the phone number itself. No control eliminates every attack, but moving critical accounts away from SMS-only verification reduces the value of a stolen number.
Protect your primary email
Use a unique password, strong MFA, updated recovery information and alerts. If an attacker controls your email, the criminal can often reset many other accounts even after the phone number is restored.
How to prepare an insurance claim
Notify the insurer promptly and ask which coverage section applies. Provide a timeline showing when service disappeared, when the carrier confirmed the unauthorized swap, which accounts were accessed and what financial loss occurred. Keep bank investigation results and any recovery amounts because the insurer may need to calculate the net covered loss.
Frequently asked questions
Will cyber insurance reimburse money stolen after a SIM swap?
It depends on the policy. Some personal cyber products cover defined online fraud or unauthorized transfer losses, often subject to sublimits and exclusions. Never assume all stolen funds are insured.
Is text-message two-factor authentication useless?
No. The FTC says text verification is better than having no additional factor when it is the only option, but authenticator apps or security keys are safer against SIM-swap attacks.
What should I do first if my number is hijacked?
Contact the mobile carrier immediately to regain control, then secure email and financial accounts and report unauthorized activity.
Does identity theft insurance prevent SIM swapping?
No. Insurance can provide defined recovery services or reimbursement after an incident. Prevention depends on account security and carrier controls.
Sources & further reading
Reviewed October 6, 2026. Cyber policy wording and financial-institution remedies vary. Report suspected account takeover immediately and verify your actual coverage before assuming reimbursement.
